Latest CVE Feed
-
5.9
MEDIUMCVE-2021-38548
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the po... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38547
Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected dir... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38546
CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to... Read more
Affected Products : pebble_v3_firmware pebble_v2_firmware pebble_firmware pebble_plus_firmware pebble_v3 pebble_v2 pebble pebble_plus- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38545
Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-op... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38544
Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected ... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38543
TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-o... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38542
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.... Read more
Affected Products : james- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38540
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information di... Read more
Affected Products : airflow- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38539
Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1... Read more
Affected Products : r6700_firmware r6900_firmware r6900p_firmware r7000_firmware r7000p_firmware r6400_firmware r7900_firmware d8500_firmware r7100lg_firmware r8300_firmware +14 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-38538
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40... Read more
Affected Products : r7800_firmware r8900_firmware r9000_firmware xr500_firmware d7800_firmware rax120_firmware rbk20_firmware rbr20_firmware rbs20_firmware rbk40_firmware +20 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38537
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R69... Read more
Affected Products : d6200_firmware d7000_firmware r6020_firmware r6080_firmware r6120_firmware r6260_firmware r6700_firmware r6800_firmware r6900_firmware ac2100_firmware +26 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38536
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R69... Read more
Affected Products : d6200_firmware d7000_firmware r6020_firmware r6080_firmware r6120_firmware r6260_firmware r6700_firmware r6800_firmware r6900_firmware ac2100_firmware +28 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38535
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R69... Read more
Affected Products : d6200_firmware d7000_firmware r6020_firmware r6080_firmware r6120_firmware r6260_firmware r6700_firmware r6800_firmware r6900_firmware ac2100_firmware +28 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-38534
Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 before 1.0.0.60, D6200 before 1.1.00.36, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.53, D85... Read more
Affected Products : dgn2200_firmware d3600_firmware d6000_firmware d6200_firmware d7000_firmware jr6150_firmware pr2000_firmware r6020_firmware r6050_firmware r6080_firmware +76 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38532
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-38531
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.... Read more
Affected Products : d6200_firmware d7000_firmware r6020_firmware r6080_firmware r6120_firmware r6260_firmware r6700_firmware r6800_firmware r6900_firmware ac2100_firmware +14 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-38530
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2... Read more
Affected Products : rbk20_firmware rbr20_firmware rbs20_firmware rbk40_firmware rbr40_firmware rbs40_firmware rbk50_firmware rbr50_firmware rbs50_firmware rbs50y_firmware +10 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38529
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.... Read more
Affected Products : r7800_firmware r8900_firmware r9000_firmware d7800_firmware d7800 r9000 r8900 r7800- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-38528
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.... Read more
Affected Products : r6900p_firmware r7000p_firmware xr300_firmware d8500_firmware r7100lg_firmware wndr3400_firmware r7100lg d8500 r6900p r7000p +2 more products- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024